Microsoft's Biggest-Ever Security Update Just Landed — And It Fixes Nearly 1,000 Bugs at Once
Microsoft's September 2026 Patch Tuesday fixed a record 973 vulnerabilities, including two actively exploited Windows zero-days now added to CISA's Known Exploited Vulnerabilities catalog.
If your IT team looked overwhelmed this week, there's a good reason: Microsoft just shipped the largest single security update in its history.
Microsoft released its September 2026 Patch Tuesday updates on Tuesday, addressing 973 vulnerabilities across Windows, Microsoft Office, SQL Server, Exchange Server, SharePoint, Azure, and developer tools — smashing the previous record set just two months earlier, when July's update fixed 570 flaws. August's release, by comparison, covered 421 vulnerabilities. September's total more than doubles that.
Two of the fixed vulnerabilities were already being actively exploited by attackers before the patches shipped, and the Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities catalog the same day — a designation that typically signals real, ongoing risk rather than a theoretical concern.
The first, CVE-2026-85880, is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), a system Windows uses for communication between processes. An attacker who already has some level of access to a machine could exploit the flaw locally to gain SYSTEM privileges — the highest level of access on a Windows device. The second, CVE-2026-81963, involves a link-following flaw in the Windows Update Stack, similarly allowing a local attacker to escalate to SYSTEM-level control. Both carry a CVSS severity score of 7.8 and are rated "Important" by Microsoft, though the confirmed exploitation makes both an immediate patching priority regardless of the rating.
Windows accounted for the bulk of this month's fixes, with 723 vulnerabilities addressed in that product line alone, followed by Office (111), SQL Server (62), developer tools (22), SharePoint Server (16), and Exchange Server (9). Elevation-of-privilege issues made up nearly half of all fixes, with remote code execution vulnerabilities forming the second-largest category. Of the total, 113 vulnerabilities were rated critical, and 20 were flagged as potentially "wormable" — capable of spreading automatically between systems without user interaction.
One vulnerability drawing particular attention from security researchers is CVE-2026-55007, affecting Exchange Server, which could let a remote, unauthenticated attacker execute code simply by sending an email containing a malicious Visio attachment — a genuinely low-effort attack vector for a high-impact vulnerability.
The scale of this release ties into a broader shift in how Microsoft is finding these bugs in the first place. The company has been expanding a proprietary, AI-assisted vulnerability scanning system across its entire Windows codebase in recent months — a development several outlets have linked directly to the sharp rise in vulnerabilities being caught and patched in a single monthly cycle.
Security teams are being advised to treat the two confirmed zero-days as immediate priorities: identifying exposed Windows endpoints, deploying the cumulative September updates through established change-management processes, and reviewing endpoint detection systems for signs of unusual privilege-escalation activity or unexpected administrative tool usage. Given the sheer size of this release, though, experts are also cautioning against tunnel vision — focusing exclusively on the two headline zero-days risks leaving hundreds of other significant vulnerabilities unpatched, any of which could become active exploitation targets once technical details circulate more widely.
Know something we don't? Tip us at tips@kanilprwire.com.